PT-2011-5045 · Pixie · Pixie Cms

Piranha

·

Published

2011-12-08

·

Updated

2021-03-29

·

CVE-2011-4710

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pixie CMS versions 1.01 through 1.04
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the pixie user parameter and the Referer HTTP header in a request to the default URI.
Recommendations For Pixie CMS versions 1.01 through 1.04, consider restricting access to the default URI and avoid using the pixie user parameter until a fix is available. As a temporary workaround, restrict the Referer HTTP header to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4710

Affected Products

Pixie Cms